← Vulnerability feed

Vulnerability record · CVE-2008-1423 · published 16 May 2008

CVE-2008-1423: Xiph.org libvorbis vulnerability

XXiph.Org · Libvorbis

Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.

9.3 CVSS 2.0 High EPSS 8.1% · top 5.4% CWE-189 · CWE-189
9.3CVSS 2.0 base score
8.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
48References
16 Jun 2026Last modified by NVD

Description

Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html Third Party Advisory
http://secunia.com/advisories/30234 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30237 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30247 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30259 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30479 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30581 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30820 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/32946 Permissions RequiredThird Party Advisory
http://security.gentoo.org/glsa/glsa-200806-09.xml Third Party Advisory
http://www.debian.org/security/2008/dsa-1591 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:102 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0270.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2008-0271.html Not Applicable
http://www.securityfocus.com/bid/29206 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020029 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-682-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/1510/references Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=440709 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/42403
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9851
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00243.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00247.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00256.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html Third Party Advisory
http://secunia.com/advisories/30234 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30237 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30247 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30259 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30479 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30581 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30820 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/32946 Permissions RequiredThird Party Advisory
http://security.gentoo.org/glsa/glsa-200806-09.xml Third Party Advisory
http://www.debian.org/security/2008/dsa-1591 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:102 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0270.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2008-0271.html Not Applicable
http://www.securityfocus.com/bid/29206 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020029 Third Party AdvisoryVDB Entry

Track CVE-2008-1423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14632Xiph.org libvorbis memory buffer overflow vulnerabilityXiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…EPSS 5.7%8.8CVE-2018-10392Xiph.org libvorbis out-of-bounds read vulnerabilitymapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …EPSS 3.3%8.8CVE-2017-14160Xiph.org libvorbis memory buffer overflow vulnerabilityThe bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …EPSS 4.6%7.5CVE-2018-10393Xiph.org libvorbis out-of-bounds read vulnerabilitybark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.EPSS 2.4%6.8CVE-2008-1420Xiph.org libvorbis vulnerabilityInteger overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…EPSS 6.3%6.5CVE-2020-20412Stepmania vulnerabilitylib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG fi…EPSS 1.0%6.5CVE-2017-14633Xiph.org libvorbis out-of-bounds read vulnerabilityIn Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…EPSS 1.9%5.5CVE-2017-11333Xiph.org libvorbis null pointer dereference vulnerabilityThe vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafte…EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2008-1423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.